ZDI-CAN-19120: ZDI-23-1771: Microsoft Excel SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2022-26804.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19120?
The ZDI-CAN-19120 vulnerability has a high severity rating due to its capability to allow remote code execution on Microsoft Excel.
How do I fix ZDI-CAN-19120?
To remediate ZDI-CAN-19120, ensure that you have installed the latest security updates provided by Microsoft for Excel.
What types of attacks can exploit ZDI-CAN-19120?
ZDI-CAN-19120 can be exploited through malicious web pages or files that require user interaction to execute arbitrary code.
Which software versions are affected by ZDI-CAN-19120?
ZDI-CAN-19120 affects Microsoft Excel for Mac installations.
Is user interaction needed to exploit ZDI-CAN-19120?
Yes, a user must visit a malicious page or open a malicious file to exploit the ZDI-CAN-19120 vulnerability.